CVE-2019-19202
21.11.2019, 20:15
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.Enginsight
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 7.0 ≤ 𝑥 < 7.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration